Forecraft

Privacy Policy

Last updated: June 9, 2026

Contents

  1. 1. Who We Are
  2. 2. What Data We Collect
  3. 3. How We Use Your Data
  4. 4. How We Do Not Use Your Data
  5. 5. Data Sharing and Sub-Processors
  6. 6. Data Retention
  7. 7. Your Rights
  8. 8. Cookies and Tracking
  9. 9. Data Security
  10. 10. International Data Transfers
  11. 11. Children
  12. 12. Contact for Privacy
  13. 13. Changes to This Policy
Terms of ServiceData Processing AddendumSecurityPlain-English Data Guide

1. Who We Are

Forecraft (“Forecraft,” “we,” “us,” or “our”) operates the financial close workflow platform available at forecraft.tech.

ForeCraft is a financial close workflow platform. For GDPR purposes, see the contact address below. Legal entity details will be updated upon formal incorporation.

For GDPR purposes, Forecraft acts as a data processor with respect to the financial data you upload on behalf of your clients, and as a data controller with respect to your account data and usage data.

2. What Data We Collect

Data you provide directly

Account data
Name, email address, and password (stored as a bcrypt hash — never in plain text).
Workspace and firm settings
Firm name, client workspace names, brand colors, logo, accounting method preferences, and other configuration you set up within the Service.
Financial data
Profit & loss files, balance sheets, budget files, and any other financial documents you upload or that Forecraft pulls from accounting integrations on your request. This is your clients’ financial data — you retain ownership of it.
Payment data
Payment processing is handled entirely by Stripe. We store only your Stripe Customer ID and Subscription ID. We never store your card number, bank account details, or any payment credentials.
Communications
Emails you send to our support or privacy addresses, feedback submitted through the Service, and any other communications with us.

Data collected automatically

Usage data
Pages visited, features used, actions taken within the Service, and timestamps. Usage logs do not contain the content of your financial data — only interaction events (e.g., “report generated,” “file uploaded”).
Authentication and security logs
Login times, IP addresses, and device information. Retained for 90 days for security and fraud prevention purposes.
Technical data
Browser type, operating system, and device type, used to ensure compatibility and investigate errors.

Data from integrations

QuickBooks Online / Xero
If you connect an accounting integration, Forecraft retrieves financial reports (P&L, balance sheets) from that integration on your explicit request. OAuth tokens that authorize this access are encrypted at rest. You may disconnect an integration at any time from Settings.

3. How We Use Your Data

Account data
To create and manage your account, authenticate you, and communicate with you about your subscription and the Service.
Financial data
To generate close packs, variance analysis, and management reports — the core purpose of the Service. Financial data is processed only to provide these features to you.
AI processing
When you use AI-powered features (executive narrative, variance explanations), relevant financial data is sent to Anthropic’s API to generate the requested text. This data is processed for that request only. Anthropic’s API terms prohibit using API inputs to train or improve their models without customer consent — we have not granted that consent. See Anthropic’s Privacy Policy for their practices.
Authentication logs
To detect and prevent unauthorized access to your account. Retained for 90 days.
Usage data
To understand how the Service is used and to improve features and performance. This data is aggregated and not linked to specific financial data.
Payment data
Processed by Stripe to manage subscriptions and billing. We receive confirmation of payment status only.
Communications
To respond to your support requests and to send transactional communications (account verification, password reset, billing notifications).

4. How We Do Not Use Your Data

We want to be explicit about what we do not do:

  • We do not sell your personal data or your clients’ financial data.
  • We do not use financial data to train any AI model — Forecraft’s or anyone else’s.
  • We do not share your data with advertisers or ad networks.
  • We do not build profiles of you or your clients for advertising or marketing purposes.
  • We do not use your clients’ financial data for any purpose other than providing the Service to you.

5. Data Sharing and Sub-Processors

We share data only with the service providers necessary to operate the Service (“sub-processors”). All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security.

Vercel — Hosting and infrastructure
Our application runs on Vercel’s platform (United States). Financial data passes through Vercel’s servers to reach our database.
Neon — Database
Your financial data, account data, and workspace data are stored in Neon’s PostgreSQL database (United States). Database connections are encrypted.
Anthropic — AI narrative generation
Financial data is sent to Anthropic’s API only when you use AI features, and only for that request. Data is minimized to what is necessary for the feature.
Stripe — Payment processing
Billing data is processed by Stripe. We do not receive or store raw payment credentials. Subject to Stripe’s Privacy Policy.
Upstash — Rate limiting and session management
Used for Redis-based rate limiting on authentication routes. Does not store financial data.
Resend — Transactional email
Used to send verification emails, password resets, and billing notifications. Email addresses are shared only for delivery.
Sentry — Error monitoring
Application errors are reported to Sentry for debugging. Error reports are scrubbed of financial data before transmission.

Sub-processor details

Sub-processorRoleData locationEU transfer mechanism
Vercel Inc.Hosting & infrastructureUnited StatesStandard Contractual Clauses
Neon Inc.Database (PostgreSQL)United StatesStandard Contractual Clauses
Anthropic PBCAI narrative generationUnited StatesStandard Contractual Clauses
Stripe Inc.Payment processingUnited StatesStandard Contractual Clauses
Upstash Inc.Rate limiting & cachingUnited StatesStandard Contractual Clauses
Resend Inc.Transactional emailUnited StatesStandard Contractual Clauses

Legal disclosures

We may disclose your data if required to do so by law, court order, or government authority. Where permitted, we will notify you before complying with such a request.

Business transfers

If Forecraft is involved in a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

6. Data Retention

Account and financial data
Retained while your account is active, plus 30 days after cancellation or termination to allow data export. After 30 days, permanently deleted.
Authentication and security logs
Retained for 90 days, then automatically purged.
Deleted workspace data
Removed from active systems within 30 days of deletion and from backup systems within 90 days.
Stripe payment records
Retained per Stripe’s own data retention policies.

7. Your Rights

All users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion:Request deletion of your account and all associated data. Use “Delete account” in Account Settings or email privacy@forecraft.tech.
  • Export: Download all your data at any time from Account Settings.
  • Portability: Receive your data in a machine-readable format on request.

GDPR — EEA and UK users

If you are located in the European Economic Area or the United Kingdom, you also have:

  • The right to restrict processing of your personal data.
  • The right to object to processing based on legitimate interests.
  • The right not to be subject to automated decision-making with significant effects.
  • The right to lodge a complaint with your local supervisory authority.

Legal basis for processing: (a) contract performance — to provide the Service; (b) legitimate interests — for security and service improvement; (c) legal obligation — where required by law.

Legal basis for processing (GDPR Article 6)

For users in the European Union, ForeCraft processes personal data under the following legal bases:

Contract performance (Article 6(1)(b))
Processing your account data, workspace data, and payment information is necessary to provide the ForeCraft service you have contracted for.
Legitimate interests (Article 6(1)(f))
Processing authentication logs and security monitoring data is necessary for our legitimate interest in securing the platform and preventing unauthorized access.

We do not process data on the basis of consent except for non-essential analytics cookies where you have explicitly opted in via the cookie consent banner.

CCPA — California users

  • Right to know what personal information we collect.
  • Right to delete your personal information.
  • Right to opt out of sale — we do not sell personal information.
  • Right to non-discrimination for exercising CCPA rights.

To exercise any rights, contact privacy@forecraft.tech. We respond within 45 days for CCPA requests and 30 days for GDPR requests.

8. Cookies and Tracking

Session cookies
Required for authentication. Expire when you close your browser or after 30 days.
Preference cookies
Store UI settings such as workspace selection.

We do not use advertising cookies, third-party tracking cookies, or behavioral profiling.

A cookie consent banner is shown on first visit. You may accept essential cookies only, or opt in to analytics. Your preference is stored for 12 months.

9. Data Security

  • Encryption in transit: TLS 1.3.
  • Encryption at rest: AES-256.
  • Passwords hashed with bcrypt (cost factor 12) — never stored in plain text.
  • OAuth tokens for integrations encrypted at rest.
  • Workspace isolation — users in one workspace cannot access another.
  • Two-factor authentication (TOTP) available for all accounts.
  • Rate limiting on authentication endpoints.
  • Regular security reviews.

Breach notification: We will notify you of a breach affecting your data without undue delay and within 72 hours where required by GDPR. See our Security page for full detail.

10. International Data Transfers

Forecraft’s infrastructure is located in the United States. If you access the Service from the EEA, UK, or another jurisdiction with data transfer restrictions, your data will be transferred to and processed in the United States.

International transfers from the EEA and UK are made under Standard Contractual Clauses (SCCs) as adopted by the European Commission (2021/914). A copy of the applicable SCCs is incorporated into our Data Processing Addendum. For UK users, transfers comply with the UK International Data Transfer Agreement (IDTA).

11. Children

Forecraft is not directed to individuals under 18. We do not knowingly collect data from minors. Contact privacy@forecraft.tech if you believe we have collected data from a minor.

12. Contact for Privacy

privacy@forecraft.tech

13. Changes to This Policy

We will notify you of material changes by email at least 30 days before they take effect. Continued use after the effective date constitutes acceptance.

Last updated: June 9, 2026


See also: Terms of Service · Acceptable Use Policy · Data Processing Addendum · Security · Plain-English Data Guide

Terms of ServiceDPASecurityBack to home